
Azure AD Engineer
Posted Aug 25

Posted Aug 25
This is a fully remote position, open to applicants in United States.
• Deliver expert-level engineering and operational assistance for Microsoft Entra ID (Azure AD) within a hybrid identity setting.
• Facilitate secure interagency B2B collaboration throughout Federal enterprises.
• Lead and provide support for technical site evaluations related to new B2B partner integrations.
• Assess identity architectures, authentication workflows, conditional access policies, cross-tenant access configurations, and overall security posture.
• Create and implement integration and enablement strategies that adhere to federal security standards and client specifications.
• Set up and oversee Entra ID B2B collaboration, cross-tenant access regulations, multi-tenant organizations/cross-tenant synchronization, external identities, guest lifecycle governance, conditional access, and authentication controls.
• Aid in intake processes and enablement workflows to facilitate scalable onboarding of partner organizations and initiatives.
• Provide Tier 3 engineering support for B2B authentication, federation, provisioning, and access-control incidents, adhering to defined resolution timelines.
• Design and establish secure authentication integrations, including federation, SSO, external identity governance, and least-privilege access controls.
• Prepare and maintain interconnect documentation, such as ISA, MOU, MOA, and MFR, that reflects the implemented technical controls.
• Create repeatable templates, runbooks, and documentation standards.
• Collaborate with cybersecurity, infrastructure, and application stakeholders to satisfy federal cybersecurity requirements and align with VA Handbook 6500 standards.
• Engage in release management and coordinate B2B-related modifications across stakeholders.
• Maintain knowledge repositories, technical documentation, and training resources.
• Assist in custom identity integration engineering for agency-specific collaboration requirements.
• Contribute to initiatives aimed at continuous improvement, focusing on scalability, automation, and security posture.
• Bachelor's degree in Information Technology or a related discipline, or equivalent professional experience.
• At least seven (7) years of progressive IT experience.
• A minimum of five (5) years of practical experience with Microsoft Entra ID / Azure AD engineering in large-scale enterprise or federal settings.
• Experience in conducting tenant assessments and designing as well as implementing Entra ID B2B and external identity solutions in hybrid Active Directory environments.
• Proven track record in leading identity-focused site assessments, developing integration and enablement strategies, and executing secure cross-tenant collaboration and synchronization configurations.
• Hands-on experience in configuring conditional access policies, authentication methods, federation, identity governance controls, and cross-tenant access settings.
• Familiarity with ATO and/or ATC processes, including drafting or contributing to ISA, MOU, MOA, and MFR documentation aligned with implemented technical controls.
• Relevant Microsoft identity and security certifications and/or ITIL Foundation are preferred; equivalent advanced-level enterprise experience may be accepted in lieu of specific certifications.
• Proficiency in Microsoft Entra ID / Azure AD, External Identities (B2B), Cross-Tenant Access Policies, Conditional Access, Identity Protection, Access Reviews, PIM, Hybrid Identity, and Federation Services.
• Knowledge of hybrid identity architecture, on-premises Active Directory integration, directory synchronization, identity lifecycle management, and authentication flow design.
• Understanding of VA Handbook 6500, RMF control mapping, ATO/ATC support documentation, and NIST 800-53.
• Experience with identity federation, SSO configurations, secure partner onboarding workflows, guest lifecycle governance, and least-privilege access models.
• Proficiency in PowerShell, AzureAD, Microsoft Graph, and Entra modules.
• Familiarity with SLA-driven support models, release management coordination, intake processes, and knowledge repository upkeep.
• Experience in developing ISA, MOU, MOA, MFR artifacts, security architecture diagrams, integration plans, and technical runbooks.
• Experience in incident response support, authentication threat mitigation, identity risk monitoring, and secure configuration validation.
• Must meet eligibility for a position designated with Moderate Risk sensitivity and undergo a government background investigation.
• Current VA Tier 2/Moderate Background Investigation or equivalent, such as DoD Tier 3/NACLC or Active Secret, is preferred.
• Must be able to sit and stand for extended periods.
• Occasional travel and overtime may be necessary.
• Comprehensive benefits package.
• Collaborative work environment.
• Strong company culture.
• Veterans and military spouses are encouraged to apply.
Hightouch
Turner & Townsend
Turner & Townsend
Get handpicked remote jobs straight to your inbox weekly.